home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Network threat fields

These fields exist in the details of Lookout threat events where event.details.type=NETWORK.

Lookout event field Type LEEF field Description
*event.details.ssid
String
lookoutSSID
The wireless network ID.
*event.details.macAddress
String
lookoutMacAddress
The MAC address.
event.details.proxyProtocol
String
lookoutProxyProtocol
The proxy protocol being used.
event.details.proxyPort
Integer
lookoutProxyPort
The proxy port being used.
event.details.proxyAddress
String
lookoutProxyAddress
The proxy IP address.
event.details.vpnLocalAddress
String
lookoutVpnLocalAddress
The VPN IP address.
event.details.vpnPresent
Boolean
lookoutVpnPresent
Indicates if a VPN exists.
event.details.dnsIpAddresses
String array
lookoutDnsIpAddress
List of IP addresses.

* Indicates a field that is omitted when you enable privacy controls.